Today's report Older
Source: Security Rabbits
The Rabbit's Foot (TLDR)
Critical WordPress Plugin Vulnerabilities Enable Full Site Takeover
Multiple WordPress plugins (Pods, User Profile Builder, User Session Synchronizer, 6Storage Rentals, TrueBooker) have critical authentication bypass or account takeover flaws. Update all plugins immediately to prevent unauthenticated attackers from gaining admin access.
RapiSafe Plugin Flaw Allows Arbitrary File Deletion Leading to RCE
A critical vulnerability in RapiSafe – Secure Multi File Upload for Contact Form 7 lets unauthenticated attackers delete files like wp-config.php, potentially achieving remote code execution. Update the plugin without delay.
SiYuan Authentication Bypass Enables Remote Admin Access
SiYuan's Basic Authentication has a critical flaw allowing unauthenticated brute-force of the admin access code without rate limiting. Upgrade to version 3.7.4 or later to prevent full administrative takeover.
Active Exploitation: macOS Screen Sharing Flaw and GeoServer Zero-Day
Attackers are exploiting a macOS Screen Sharing vulnerability to install Monero miners, and an unpatched GeoServer zero-day is being probed for SQL injection/RCE. Patch or mitigate these exposures immediately.
Expired Domains Weaponized for Malware Delivery
Cybercriminals are re-registering expired domains to leverage their reputation and traffic for malware distribution and C2 operations. Review your domain portfolio and ensure expired domains are not left vulnerable to takeover.
Source: CVE Trend
Trending vulnerability
CVE-2026-15826
User Profile Builder
    Published: 2026-08-15
    Updated: 2026-08-15




πŸ₯• πŸ₯• βšͺ βšͺ βšͺ βšͺ βšͺ βšͺ βšͺ βšͺ
(21%)
The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an ..
Source: NIST
NIST CVE
A critical authorization bypass in the Pods WordPress plugin allows unauthenticated attackers to escalate privileges to Administrator or overwrite any user's password, leading to complete site takeover. Update to a patched version immediately.
An authentication bypass in the User Session Synchronizer plugin allows unauthenticated attackers to log in as any user, including administrators, due to a predictable encryption key and missing validation. This can lead to full account takeover; update the plugin without delay.
The 6Storage Rentals plugin has an authentication bypass vulnerability, allowing unauthenticated attackers to log in as any existing user, including administrators, by simply submitting their email address. Immediate action is required to update this plugin.
A critical authentication bypass via type confusion in the User Profile Builder plugin allows unauthenticated attackers to log in as the site's Administrator (user ID 1). This can result in full administrative takeover; update the plugin immediately.
The TrueBooker plugin is vulnerable to account takeover, allowing unauthenticated attackers to change any user's email address, including an administrator's, and then use the password reset flow to gain control. Update this plugin immediately.
A critical arbitrary file deletion vulnerability in the RapiSafe plugin allows unauthenticated attackers to delete files like wp-config.php, potentially leading to remote code execution. The required nonce is exposed publicly; update the plugin immediately.
A critical authentication bypass in SiYuan's Basic Authentication allows unauthenticated remote attackers to brute-force the admin access code without rate limiting, granting full administrator access to the kernel. Update to version 3.7.4 or later immediately.
Other software at risk
News
Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware
Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a [...] (Security Affairs)
macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
Hackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online. The Dutch National Cyber Security Centre confirmed active exploitation of a critical macOS authentication flaw, [...] (Security Affairs)
GeoServer Zero-Day Is Already Being Probed. That’s the Problem
GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch [...] (Security Affairs)
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. [...] (BleepingComputer)
Source: Ransomware.live
Ransomware attacks
⚠️ xpl0itrs
*********  \\ RapidFort  \\ Oz Hair & Beauty
πŸ€– spacebears
SEARS (Grupo Sanborns)
πŸ•·οΈ securotrop
Lepi Enterprises
πŸ‘ Panzer
Alpine Electronics Europe
🦨 ms13089
servmarmg.cl
πŸ•·οΈ direwolf
AAM:HOA Management  \\ TOTVS  \\ PayrHealth  \\ DXS International  \\ DodoPayments  \\ Colla Health
🎯 blackwater
www.amca.org.ar  \\ www.shalina.com
🚨 Barracuda
VR Advogados
πŸ¦‡ anubis
Interim HealthCare
Source: Hybrid Analysis
Top malicious URL
Source: Hybrid Analysis
Top malicious files